Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 154340 - net-dns/bind multiple versions vulnerable to OpenSSL RSA forgery attack
Summary: net-dns/bind multiple versions vulnerable to OpenSSL RSA forgery attack
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal
Assignee: Gentoo Security
URL: http://marc.theaimsgroup.com/?l=bind-...
Whiteboard: A3 [noglsa] aetius
Keywords:
Depends on:
Blocks:
 
Reported: 2006-11-07 03:58 UTC by Matt Drew (RETIRED)
Modified: 2007-03-14 00:22 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matt Drew (RETIRED) gentoo-dev 2006-11-07 03:58:03 UTC
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4339

Versions affected:
	BIND 9.0.x (all versions of BIND 9.0)
	BIND 9.1.x (all versions of BIND 9.1)
	BIND 9.2.0, 9.2.1, 9.2.2, 9.2.3, 9.2.4, 9.2.5, 9.2.6, 9.2.6-P1,
	     9.2.7b1, 9.2.7rc1 and 9.2.7rc2
	BIND 9.3.0, 9.3.1, 9.3.2, 9.3.2-P1, 9.3.3b1, 9.3.3rc1 and 9.3.3rc2
        BIND 9.4.0a1, 9.4.0a2, 9.4.0a3, 9.4.0a4, 9.4.0a5, 9.4.0a6, 9.4.0b1
	     and 9.4.0b2

We have a number of these in portage, including stable.  The fix is to recompile against a good version of OpenSSL and then update keys, so it requires user action.  USE="ssl" is a default for bind-9.3.2-r4 which is the current stable.
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-11-20 22:36:28 UTC
Bind please comment and bump as necessary.
Comment 2 Konstantin Arkhipov (RETIRED) gentoo-dev 2007-01-12 20:10:50 UTC
so i should bump 'em all with "good" openssl in DEPEND?
Comment 3 Matt Drew (RETIRED) gentoo-dev 2007-01-12 22:15:21 UTC
I believe so. :)

see:

http://www.gentoo.org/security/en/glsa/glsa-200609-05.xml

for the minimum openssl and baselibs (amd64) versions.
Comment 4 Stefan Cornelius (RETIRED) gentoo-dev 2007-02-26 15:47:29 UTC
sup here?
Comment 5 Matt Drew (RETIRED) gentoo-dev 2007-03-03 21:59:50 UTC
So ... events have overtaken this bug and GLSA 200702-06 should have caused everyone to upgrade and rebuild against good openSSL versions.  I think we can close this (though there is some tree cleanup remaining for vulnerable bind versions).